« Volver al listado

CVE-2026-98369

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()

syzbot reported a suspicious RCU usage warning in ip6_pkt_drop():

When commit 4f4920669d21 ("xfrm: Reinject transport-mode packets through workqueue") converted xfrm_trans_reinject from a tasklet to a workqueue, the reinjection loop ceased running in softirq context. Workqueue workers run in process context where local_bh_disable() does not enter an RCU read-side critical section under CONFIG_PREEMPT_RCU.

Because finish callbacks (such as ip6_rcv_finish) expect to run under an RCU read lock (performing route lookups, l3mdev lookups, and accessing RCU-protected data structures), invoking them in workqueue context without rcu_read_lock() triggers RCU lockdep warnings.

Leer descripción completaMostrar menos

Furthermore, packets queued to the workqueue via xfrm_trans_queue_net() may carry non-refcounted (noref) dst entries (e.g. from ip_route_input_noref). Additionally, on netdevice unregistration, dst_dev_put() replaces dst->dev with blackhole_netdev, so dst entries do not keep skb->dev alive while queued in the workqueue.

Fix these issues by: 1. Calling skb_dst_force(skb) in xfrm_trans_queue_net() while still in the caller's RCU section to ensure dst is reference-counted before queuing. 2. Holding a reference on skb->dev via dev_hold()/dev_put() across workqueue deferral so skb->dev remains valid during finish() callback processing. 3. Acquiring rcu_read_lock() around the finish callback invocation loop in xfrm_trans_reinject().

Detalles técnicos trazas, registros y código del informe original
  WARNING: suspicious RCU usage in ip6_pkt_drop
  include/net/addrconf.h:389 suspicious rcu_dereference_check() usage!

  Call Trace:
   __in6_dev_get_safely include/net/addrconf.h:389 [inline]
   ip6_pkt_drop+0x596/0x610 net/ipv6/route.c:4620
   ip6_pkt_discard+0x1c/0x30 net/ipv6/route.c:4651
   xfrm_trans_reinject+0x324/0x630 net/xfrm/xfrm_input.c:806
   process_one_work kernel/workqueue.c:3322 [inline]
   process_scheduled_works+0xa8e/0x14e0 kernel/workqueue.c:3405
   worker_thread+0xa47/0xfb0 kernel/workqueue.c:3486

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98369",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7d98b26684cb2390729525b341ea099f0badbe18",
              "lessThan": "41e47f1664be86c91326f0afe0504a1162d00907",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4f4920669d21e1060b7243e5118dc3b71ced1276",
              "lessThan": "6601d91a85761f33351c71e04ec0bbd294ca07ce",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4f4920669d21e1060b7243e5118dc3b71ced1276",
              "lessThan": "0cda8273265d30cac6423834fd7d4acb75f04fdb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4f4920669d21e1060b7243e5118dc3b71ced1276",
              "lessThan": "68a317b4aec8ca1868a39d69e40f9e29baa4f40a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4f4920669d21e1060b7243e5118dc3b71ced1276",
              "lessThan": "6eb3b071be8e260543c604550c54dac66e6b174b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4f4920669d21e1060b7243e5118dc3b71ced1276",
              "lessThan": "664fc0941df7c1918b2cd4de6ee00469ba77d8e4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4f4920669d21e1060b7243e5118dc3b71ced1276",
              "lessThan": "d2f5082f9e84653fa1a9e8aebaaff23e688f5e19",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f520075da484306bbb8425afd2c42404ba74816f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "130d9e5017ade1b81d16783563edb38c12a2eab7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.15.75",
              "lessThan": "5.15.222",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.19.17",
              "lessThan": "5.20",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.0.3",
              "lessThan": "6.1",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/xfrm/xfrm_input.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/xfrm/xfrm_input.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:31.280",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0cda8273265d30cac6423834fd7d4acb75f04fdb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/41e47f1664be86c91326f0afe0504a1162d00907",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6601d91a85761f33351c71e04ec0bbd294ca07ce",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/664fc0941df7c1918b2cd4de6ee00469ba77d8e4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/68a317b4aec8ca1868a39d69e40f9e29baa4f40a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6eb3b071be8e260543c604550c54dac66e6b174b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d2f5082f9e84653fa1a9e8aebaaff23e688f5e19",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()\n\nsyzbot reported a suspicious RCU usage warning in ip6_pkt_drop():\n\n  WARNING: suspicious RCU usage in ip6_pkt_drop\n  include/net/addrconf.h:389 suspicious rcu_dereference_check() usage!\n\n  Call Trace:\n   __in6_dev_get_safely include/net/addrconf.h:389 [inline]\n   ip6_pkt_drop+0x596/0x610 net/ipv6/route.c:4620\n   ip6_pkt_discard+0x1c/0x30 net/ipv6/route.c:4651\n   xfrm_trans_reinject+0x324/0x630 net/xfrm/xfrm_input.c:806\n   process_one_work kernel/workqueue.c:3322 [inline]\n   process_scheduled_works+0xa8e/0x14e0 kernel/workqueue.c:3405\n   worker_thread+0xa47/0xfb0 kernel/workqueue.c:3486\n\nWhen commit 4f4920669d21 (\"xfrm: Reinject transport-mode packets through\nworkqueue\") converted xfrm_trans_reinject from a tasklet to a workqueue,\nthe reinjection loop ceased running in softirq context. Workqueue workers\nrun in process context where local_bh_disable() does not enter an RCU\nread-side critical section under CONFIG_PREEMPT_RCU.\n\nBecause finish callbacks (such as ip6_rcv_finish) expect to run under an\nRCU read lock (performing route lookups, l3mdev lookups, and accessing\nRCU-protected data structures), invoking them in workqueue context without\nrcu_read_lock() triggers RCU lockdep warnings.\n\nFurthermore, packets queued to the workqueue via xfrm_trans_queue_net()\nmay carry non-refcounted (noref) dst entries (e.g. from ip_route_input_noref).\nAdditionally, on netdevice unregistration, dst_dev_put() replaces dst->dev\nwith blackhole_netdev, so dst entries do not keep skb->dev alive while\nqueued in the workqueue.\n\nFix these issues by:\n1. Calling skb_dst_force(skb) in xfrm_trans_queue_net() while still in the\n   caller's RCU section to ensure dst is reference-counted before queuing.\n2. Holding a reference on skb->dev via dev_hold()/dev_put() across workqueue\n   deferral so skb->dev remains valid during finish() callback processing.\n3. Acquiring rcu_read_lock() around the finish callback invocation loop in\n   xfrm_trans_reinject()."
    }
  ],
  "lastModified": "2026-10-06T09:18:31.280",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}